Document status: Draft for legal/privacy reviewLast updated: 2026-02-17Owner: Legal + Privacy

This summary is publication-safe orientation content and not a full DPA agreement.

GDPR role model by deployment mode

Deployment modeRole postureNotes
SmartClover managed SaaSMixed controller/processor model by processing purposeRole allocation must be explicitly documented contractually per data flow.
Customer-managed private deploymentSmartClover acts as processor/support provider for defined instructionsCustomer typically remains primary controller for core processing activities.
Hybrid or on-edge deploymentMixed model with annex-level role allocationNo implicit role assumptions; each flow requires explicit assignment.

DPA structure baseline

  • Role allocation matrix by deployment mode and processing purpose.
  • Documented instruction handling and confidentiality obligations.
  • Subprocessor transparency with notification process.
  • Security baseline covering access, encryption, and audit traceability.
  • Breach notification and cooperation commitments.